The importance of confidentiality in the practice of medical profession was recognised as a priority since the Hippocratic Oath. Internet caused a revolution not only in everyday life of citizens but also in the handling of health information by medical professionals. Exchange of health data can guarantee a better answer to the population health needs but also poses new risks. The European Union Agency for Network and Information Security (ENISA) published its first analysis of the cyber threat landscape of the health sector in the EU in July 2023. Hospitals faced many different cyberattacks in the last years, sometimes with important economic consequences. This article reports the main classes of possible attacks, such as phishing, ransomware, data loss or data theft, attacks to connected medical devices, and Distributed-Denial-of-Service (DDoS), and the specific targets attractive for cybercriminals in the health information technologies (HIT), such as the electronic health records (EHR), the personal health records (PHR), the booking system for clinical appointments and the administrative systems. From a medico-legal perspective, it is paramount to frame in a correct manner the issue regarding current cybercrimes targeting healthcare structures. The issue is well known for Patient Safety operators as a serious threat: a delay on data availability or the impossibility to obtain certain information in critical occasion could led to serious (if not fatal) consequences for the patient. After examining the laws involved in protecting patients and their data from cyberattwacks, we conclude that addressing these threats cannot be solely based on legal means, but also IT and risk management strategies, together with the compliance with standards such as ISO 31000 are needed for a fruitful approach with a specific focus on digital expertise of healthcare professionals as well as administrative staff involved in healthcare.

(2023). Health and Cybercrime [journal article - articolo]. In EUROPEAN REVIEW OF DIGITAL ADMINISTRATION & LAW. Retrieved from https://hdl.handle.net/10446/305487

Health and Cybercrime

Romolo, Francesco Saverio;
2023-01-01

Abstract

The importance of confidentiality in the practice of medical profession was recognised as a priority since the Hippocratic Oath. Internet caused a revolution not only in everyday life of citizens but also in the handling of health information by medical professionals. Exchange of health data can guarantee a better answer to the population health needs but also poses new risks. The European Union Agency for Network and Information Security (ENISA) published its first analysis of the cyber threat landscape of the health sector in the EU in July 2023. Hospitals faced many different cyberattacks in the last years, sometimes with important economic consequences. This article reports the main classes of possible attacks, such as phishing, ransomware, data loss or data theft, attacks to connected medical devices, and Distributed-Denial-of-Service (DDoS), and the specific targets attractive for cybercriminals in the health information technologies (HIT), such as the electronic health records (EHR), the personal health records (PHR), the booking system for clinical appointments and the administrative systems. From a medico-legal perspective, it is paramount to frame in a correct manner the issue regarding current cybercrimes targeting healthcare structures. The issue is well known for Patient Safety operators as a serious threat: a delay on data availability or the impossibility to obtain certain information in critical occasion could led to serious (if not fatal) consequences for the patient. After examining the laws involved in protecting patients and their data from cyberattwacks, we conclude that addressing these threats cannot be solely based on legal means, but also IT and risk management strategies, together with the compliance with standards such as ISO 31000 are needed for a fruitful approach with a specific focus on digital expertise of healthcare professionals as well as administrative staff involved in healthcare.
articolo
2023
Romolo, Francesco Saverio; Grassi, Simone; Di Luca, Alessandro; Previtali, Michela; Oliva, Antonio
(2023). Health and Cybercrime [journal article - articolo]. In EUROPEAN REVIEW OF DIGITAL ADMINISTRATION & LAW. Retrieved from https://hdl.handle.net/10446/305487
File allegato/i alla scheda:
File Dimensione del file Formato  
2023-Erdal_vol_4 articolo.pdf

accesso aperto

Versione: publisher's version - versione editoriale
Licenza: Licenza Free to read
Dimensione del file 1.28 MB
Formato Adobe PDF
1.28 MB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

Aisberg ©2008 Servizi bibliotecari, Università degli studi di Bergamo | Terms of use/Condizioni di utilizzo

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10446/305487
Citazioni
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact